Back to skill

Security audit

Auto Conda Env

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with Python environment setup, but it can run project-controlled install code and bypass Python package protections without clear user approval.

Install only if you are comfortable with the agent creating or changing Python environments and installing code from the target project. Review dependency files first, avoid using it on untrusted repositories, and do not allow --break-system-packages unless you have verified the interpreter and understand the risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:94
Finding

Execution of Untrusted Project Build Code and Dependencies

Content
View full analysis
-f environment.yml --prune CONDA run -n pip install . CONDA run -n pip install -r requirements.txt CONDA run -n pip install . CONDA run -n pip install pipenv && CONDA run -n pipenv sync ``` ### Technical Analysis The Skill directs the Agent to install dependencies and the current project without first establishing that the project or its dependency manifests are trusted. The `pip install .` operation may execute project-controlled build logic through a Python build backend or legacy `setup.py` behavior. An attacker can place malicious execution logic in a repository's build configuration and cause it to run during package metadata generation, wheel construction, or installation. The other commands consume project-controlled dependency manifests. These manifests can select untrusted package names, package indexes, direct URLs, VCS repositories, Conda channels, or packages vulnerable to dependency confusion. The instructions do not require lock files, package hashes, source restrictions, manifest review, or explicit user approval before installation. Although installation is intended to occur in a Conda environment, package build code executes as the user running the Agent. A virtual environment isolates Python packages but does not sandbox filesystem, process, credential, or network access. ### Attack Path 1. An attacker creates or modifies a Python project containing one or more of the following: - A malicious build backend or `setup.py` implementation. - A dependency with an attacker-controlled name or source. - A direct URL or VCS dependency hosting malicious package code. - A malicious Conda channel or package selection. 2. The victim asks the Agent to configure a ...[truncated 977 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:108
Finding

Unsafe Bypass of Externally Managed Python Protection

Content
View full analysis
Remediation
View remediation
python -c "import sys; print(sys.executable); print(sys.prefix)" CONDA run -n python -m pip --version ``` 3. Invoke pip through the verified interpreter using `python -m pip` rather than relying on executable-name resolution. 4. Confirm that `sys.prefix` belongs to the intended Conda environment and is distinct from the system interpreter prefix. 5. If PEP 668 is encountered in a purported Conda environment, treat it as an environment-selection or environment-integrity error and stop. 6. Recreate a broken environment instead of bypassing operating-system package protections. 7. If a bypass is exceptionally necessary, explain the affected interpreter and risks and require explicit user approval. 8. Never use this flag with elevated privileges or against a system-wide Python installation. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest lists generic triggers such as "配置python环境", "python环境配置", "setup python env", and "project environment" without clear exclusions or tighter context. These phrases can match ordinary conversation about Python setup, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to create environments and execute package installation commands, including pip install ., pip install -r requirements.txt, conda env update, and even retrying with --break-system-packages, without a clear upfront warning that these actions will modify local environments and execute potentially untrusted project packaging logic. In this context, dependency files and local project installs can trigger installation of arbitrary packages or package build hooks, so lack of explicit warning and consent materially increases the danger.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims it is 'read-only' with respect to existing Conda installs, but its documented behavior explicitly reuses existing environments and runs commands such as conda env update, pip install, and pipenv sync against them. This mismatch can cause unintended modification of pre-existing environments, increasing the risk of dependency drift, breakage, or supply-chain exposure when a user expects non-destructive behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The docstring states 'No file I/O needed,' which contradicts the implementation's use of os.path.realpath(file) and os.path.dirname(...) to inspect filesystem path information. Although this is limited and low risk, it is still an active mismatch between the documentation and actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.